CVE & Exploit Intelligence Database

Updated 59m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
42,457 results Clear all
CVE-2008-1211 EPSS 0.00
BosDates 3.x-4.x - XSS
Cross-site scripting (XSS) vulnerability in BosDates 3.x and 4.x allows remote attackers to inject arbitrary web script or HTML via (1) the type parameter in calendar.php and (2) the category parameter in calendar_search.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Mar 08, 2008
CVE-2008-1212 EPSS 0.00
Podcast Generator 0.96.2 - XSS
Cross-site scripting (XSS) vulnerability in set_permissions.php in Podcast Generator 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the scriptlang parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Mar 08, 2008
CVE-2008-1213 EPSS 0.00
Numara FootPrints for Linux 8.1 - XSS
Cross-site scripting (XSS) vulnerability in Numara FootPrints for Linux 8.1 allows remote attackers to inject arbitrary web script or HTML via the Title form field when setting an appointment. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Mar 08, 2008
CVE-2008-1176 1 PoC Analysis EPSS 0.01
Affiliate Market 0.1 BETA - XSS
Cross-site scripting (XSS) vulnerability in function/sideblock.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to inject arbitrary web script or HTML via the sideblock4 parameter.
CWE-79 Mar 06, 2008
CVE-2008-1183 EPSS 0.00
Crafty Syntax Live Help <2.14.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Crafty Syntax Live Help (CSLH) before 2.14.6 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) livehelp.php, (2) user_questions.php, and (3) leavemessage.php. NOTE: the lostsheep.php vector is covered by CVE-2008-0848.
CWE-79 Mar 06, 2008
CVE-2008-1173 1 PoC Analysis EPSS 0.00
TorrentTrader Classic 1.08 - XSS
Cross-site scripting (XSS) vulnerability in account-inbox.php in TorrentTrader Classic 1.08 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
CWE-79 Mar 06, 2008
CVE-2008-1175 EPSS 0.00
AuthentiX 6.3b1 Trial - XSS
Cross-site scripting (XSS) vulnerability in AuthentiX 6.3b1 Trial allows remote attackers to inject arbitrary web script or HTML via the username parameter to aspAdmin/deleteUser.asp, a different vector than CVE-2008-1174. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Mar 06, 2008
CVE-2008-1182 EPSS 0.00
pfSense <1.2 - XSS
Cross-site scripting (XSS) vulnerability in BSD Perimeter pfSense before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 06, 2008
CVE-2008-1174 1 PoC Analysis EPSS 0.01
AuthentiX 6.3b1 - XSS
Cross-site scripting (XSS) vulnerability in editUser.asp in AuthentiX 6.3b1 Trial allows remote attackers to inject arbitrary web script or HTML via the username parameter.
CWE-79 Mar 06, 2008
CVE-2008-1179 EPSS 0.00
Centreon <1.4.2.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in include/common/javascript/color_picker.php in Centreon 1.4.2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) title parameters. NOTE: some of these details are obtained from third party information.
CWE-79 Mar 06, 2008
CVE-2008-1180 1 PoC Analysis EPSS 0.08
Juniper Networks Secure Access 2000 5.5 R1 - XSS
Cross-site scripting (XSS) vulnerability in dana-na/auth/rdremediate.cgi in Juniper Networks Secure Access 2000 5.5 R1 build 11711 allows remote attackers to inject arbitrary web script or HTML via the delivery_mode parameter.
CWE-79 Mar 06, 2008
CVE-2008-1165 EPSS 0.00
Flyspray <0.9.9.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Flyspray 0.9.9 through 0.9.9.4 allow remote attackers to inject arbitrary web script or HTML via (1) a forced SQL error message or (2) old_value and new_value database fields in task summaries, related to the item_summary parameter in a details action in index.php. NOTE: some of these details are obtained from third party information.
CWE-79 Mar 05, 2008
CVE-2007-6704 2 PoCs Analysis EPSS 0.07
F5 FirePass 4100 SSL VPN <6.0.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass 4100 SSL VPN 5.4.1 through 5.5.2 and 6.0 through 6.0.1, when pre-logon sequences are enabled, allow remote attackers to inject arbitrary web script or HTML via the query string to (1) my.activation.php3 and (2) my.logon.php3.
CWE-79 Mar 05, 2008
CVE-2008-1168 EPSS 0.01
Squid Analysis Report Generator (Sarg) 2.2.3.1 - XSS
Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header, which is not properly handled when displaying the Squid proxy log. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Mar 05, 2008
CVE-2008-1098 EPSS 0.01
MoinMoin <1.5.8 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.5.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) certain input processed by formatter/text_gedit.py (aka the gui editor formatter); (2) a page name, which triggers an injection in PageEditor.py when the page is successfully deleted by a victim in a DeletePage action; or (3) the destination page name for a RenamePage action, which triggers an injection in PageEditor.py when a victim's rename attempt fails because of a duplicate name. NOTE: the AttachFile XSS issue is already covered by CVE-2008-0781, and the login XSS issue is already covered by CVE-2008-0780.
CWE-79 Mar 05, 2008
CVE-2008-1133 EPSS 0.00
Drupal 6.0 - XSS
The Drupal.checkPlain function in Drupal 6.0 only escapes the first instance of a character in ECMAScript, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
CWE-79 Mar 04, 2008
CVE-2008-1131 EPSS 0.00
Drupal 6.0 - XSS
Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms.
CWE-79 Mar 04, 2008
CVE-2008-1129 1 PoC Analysis EPSS 0.00
XRMS CRM - XSS
Cross-site scripting (XSS) vulnerability in admin/users/self.php in XRMS CRM allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Mar 04, 2008
CVE-2008-1082 EPSS 0.00
Opera <9.26 - XSS
Opera before 9.26 allows remote attackers to "bypass sanitization filters" and conduct cross-site scripting (XSS) attacks via crafted attribute values in an XML document, which are not properly handled during DOM presentation.
CWE-79 Feb 29, 2008
CVE-2008-1076 EPSS 0.00
Interspire Shopping Cart 1.x - XSS
Cross-site scripting (XSS) vulnerability in search.php in Interspire Shopping Cart 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Feb 29, 2008